CVE-2026-101891

Published on September 28, 2026

An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.

Weakness type (CWE)CWE-284, CWE-923

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database